Sunday, June 14, 2020

Hacker101 CTF: Micro-CMS v2 - Part 3

I didn't know what to do here. So, looked a hint which was
Credentials are secret, flags are secret. Coincidence?

I have no idea what it is but my guess is that secret credentials needs to be obtain to get this last flag. What options do I have? SQL injection to dump the database. The thing that we know by now is, there is a table called admins. I did a hit and trial with multiple cases

Trial 1
username: admin' OR '1' = '1
password: random
result: invalid password

Trial 2
username: user
password: random
result: invalid user

Conclusion at this point: There is a table admins with username and password column. Also, admin is one of the user in that username.

Trial 3
username: admin' OR 1=1--
password: random
result:

Traceback (most recent call last):
File "./main.py", line 145, in do_login
if cur.execute('SELECT password FROM admins WHERE username=\'%s\'' % request.form['username'].replace('%', '%%')) == 0:
File "/usr/local/lib/python2.7/site-packages/MySQLdb/cursors.py", line 255, in execute
self.errorhandler(self, exc, value)
File "/usr/local/lib/python2.7/site-packages/MySQLdb/connections.py", line 50, in defaulterrorhandler
raise errorvalue
ProgrammingError: (1064, "You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near ''' at line 1")

23 comments:

  1. very interesting. just found your site. I really like it. thanks for the content.

    ReplyDelete
    Replies
    1. FULLZ AVAILABLE WITH HIGH CREDIT SCORES 700+
      (Spammed From Credit Bureau of USA)

      =>Contact 24/7<=

      Telegram> @killhacks
      ICQ> 752822040

      FRESHLY SPAMMED
      VALID INFO WITH VALID DL EXPIRIES

      *All info included*
      NAME+SSN+DOB+DL+DL-STATE+ADDRESS
      Employee & Bank details included

      CC & CVV'S ONLY USA AVAILABLE

      $1 for SSN+DOB
      $2 for SSN+DOB+DL
      $5 for High credit fullz 700+
      (bulk order negotiable)
      *Payment in all crypto currencies will be accepted

      ->You can buy few for testing
      ->Invalid or wrong info will be replaced
      ->Serious buyers needed for long term

      PLEASE DON'T ASK ANYTHING FOR FREE

      TOOLS & TUTORIALS AVAILABLE FOR SPAMMING, HACKING & CARDING

      (Carding, spamming, hacking, scam page, Cash outs, dumps cash outs)

      Ethical Hacking Tools & Tutorials
      Kali linux
      Facebook & Google hacking
      SQL Injector
      Bitcoin flasher
      Keylogger & Keystroke Logger
      Premium Accounts (Netflix, coinbase, FedEx, Pornhub, etc)
      Paypal Logins
      Bitcoin Cracker
      SMTP Linux Root
      DUMPS with pins track 1 and 2
      Smtp's, Safe Socks, rdp's, VPN, Viruses
      Cpanel
      Php mailer
      Server I.P's & Proxies
      HQ Emails Combo

      *If you need a valid vendor it's very prime chance, you'll never be disappointed*

      CONTACT 24/7
      Telegram> @killhacks
      ICQ> 752822040

      Delete
    2. Myclassnotes: Hacker101 Ctf: Micro-Cms V2 - Part 3 >>>>> Download Now

      >>>>> Download Full

      Myclassnotes: Hacker101 Ctf: Micro-Cms V2 - Part 3 >>>>> Download LINK

      >>>>> Download Now

      Myclassnotes: Hacker101 Ctf: Micro-Cms V2 - Part 3 >>>>> Download Full

      >>>>> Download LINK bM

      Delete
    3. QUALITY SSN DOB DL HIGH CREDIT SCORES Leads
      Tutorials & E-Books For Ethical Hacking
      Tools For Everything You Need

      I'm On Telegram = @killhacks & I C Q = 752822040

      Stuff for Learning purpose
      (Spamming, Ethical Hacking, LINUX, Programming, etc. )

      Deals in all kind of Tools, Tutorials, E-books, Leads/Fullz/Pros
      Availability 24/7
      FASTEST DELIVERY

      Build Your Own Business with proper guide
      Always glad to serve

      GOOD LUCK
      Here I'm:
      I C Q = 752822040
      Tele-gram = @killhacks

      Delete
  2. Great piece of content after reading all this I'm feeling so overwhleming that I've gain some sort of knowledge from this page. Keep up the good work!! Thank YOU!
    AirBolt Review

    ReplyDelete
  3. Hi
    Thank you so much for this wonderful article really pretty good!
    ISO 27001 Consultants in Oman

    ReplyDelete
  4. **SELLING SSN+DOB FULLZ**

    CONTACT
    Telegram > @leadsupplier
    ICQ > 752822040
    Email > leads.sellers1212@gmail.com

    >>1$ each without DL/ID number
    >>2$ each with DL
    >>5$ each for premium (also included relative info)

    *Will reduce price if buying in bulk
    *Hope for a long term business

    FORMAT OF LEADS/FULLZ/PROS

    ->FULL NAME
    ->SSN
    ->DATE OF BIRTH
    ->DRIVING LICENSE NUMBER WITH EXPIRY DATE
    ->COMPLETE ADDRESS
    ->PHONE NUMBER, EMAIL, I.P ADDRESS
    ->EMPLOYMENT DETAILS
    ->REALTIONSHIP DETAILS
    ->MORTGAGE INFO
    ->BANK ACCOUNT DETAILS

    >Fresh Leads for tax returns & w-2 form filling
    >Payment mode BTC, ETH, LTC, PayPal, USDT & PERFECT MONEY

    ''OTHER GADGETS PROVIDING''

    >SSN+DOB Fullz
    >CC with CVV
    >Photo ID's
    >Dead Fullz
    >Carding Tutorials
    >Hacking Tutorials
    >SMTP Linux Root
    >DUMPS with pins track 1 and 2
    >Sock Tools
    >Server I.P's
    >HQ Emails with passwords

    Email > leads.sellers1212@gmail.com
    Telegram > @leadsupplier
    ICQ > 752822040

    THANK YOU

    ReplyDelete
  5. This content is very nice...I am glad to thank you for sharing This nice content..iso-14001-2015-lead-auditor-training

    ReplyDelete
  6. Really nice and informative..I found this blog very useful.for any ISO related queryISO Training in india

    ReplyDelete
  7. Thanks you for sharing this unique useful information content with us. Really awesome work... ISO 22000 Certification Qatar

    ReplyDelete
  8. Really nice and informative..I found this blog very useful.for any ISO related queryISO Training in INDIA

    ReplyDelete
  9. Thanks you for sharing this unique useful information content with us. Really awesome work.. ISO 45001 Certification Qatar

    ReplyDelete
  10. It is really very helpful for us and I have gathered some important information from this blog. ISO 22000 Certification

    ReplyDelete
  11. Thanks for given detail information to me. keep posting like this. iso-14001

    ReplyDelete
  12. Thanks for given detail information to me. keep posting like this. iso-14001-certification

    ReplyDelete
  13. Informative share you given here and help to perform well results in hacker.
    -hestensolutions.com-

    ReplyDelete
  14. FULLZ AVAILABLE WITH HIGH CREDIT SCORES 700+
    (Spammed From Credit Bureau of USA)

    =>Contact 24/7<=

    Telegram> @killhacks
    ICQ> 752822040

    FRESHLY SPAMMED
    VALID INFO WITH VALID DL EXPIRIES

    *All info included*
    NAME+SSN+DOB+DL+DL-STATE+ADDRESS
    Employee & Bank details included

    CC & CVV'S ONLY USA AVAILABLE

    $1 for SSN+DOB
    $2 for SSN+DOB+DL
    $5 for High credit fullz 700+
    (bulk order negotiable)
    *Payment in all crypto currencies will be accepted

    ->You can buy few for testing
    ->Invalid or wrong info will be replaced
    ->Serious buyers needed for long term

    PLEASE DON'T ASK ANYTHING FOR FREE

    TOOLS & TUTORIALS AVAILABLE FOR SPAMMING, HACKING & CARDING

    (Carding, spamming, hacking, scam page, Cash outs, dumps cash outs)

    Ethical Hacking Tools & Tutorials
    Kali linux
    Facebook & Google hacking
    SQL Injector
    Bitcoin flasher
    Keylogger & Keystroke Logger
    Premium Accounts (Netflix, coinbase, FedEx, Pornhub, etc)
    Paypal Logins
    Bitcoin Cracker
    SMTP Linux Root
    DUMPS with pins track 1 and 2
    Smtp's, Safe Socks, rdp's, VPN, Viruses
    Cpanel
    Php mailer
    Server I.P's & Proxies
    HQ Emails Combo

    *If you need a valid vendor it's very prime chance, you'll never be disappointed*

    CONTACT 24/7
    Telegram> @killhacks
    ICQ> 752822040

    ReplyDelete
  15. Myclassnotes: Hacker101 Ctf: Micro-Cms V2 - Part 3 >>>>> Download Now

    >>>>> Download Full

    Myclassnotes: Hacker101 Ctf: Micro-Cms V2 - Part 3 >>>>> Download LINK

    >>>>> Download Now

    Myclassnotes: Hacker101 Ctf: Micro-Cms V2 - Part 3 >>>>> Download Full

    >>>>> Download LINK rn

    ReplyDelete
  16. LEGIT FULLZ & TOOLS STORE

    Hello to All !

    We are offering all types of tools & Fullz on discounted price.
    If you are in search of anything regarding fullz, tools, tutorials, Hack Pack, etc
    Feel Free to contact

    ***CONTACT 24/7***
    **Telegram > @leadsupplier
    **ICQ > 752822040
    **Skype > Peeterhacks
    **Wicker me > peeterhacks

    "SSN LEADS/FULLZ AVAILABLE"
    "TOOLS & TUTORIALS AVAILABLE FOR HACKING, SPAMMING,
    CARDING, CASHOUT, CLONING, SCRIPTING ETC"

    **************************************
    "Fresh Spammed SSN Fullz info included"
    >>SSN FULLZ with complete info
    >>CC With CVV (vbv & non vbv) Fullz USA
    >>FULLZ FOR SBA, PUA & TAX RETURN FILLING
    >>USA I.D Photos Front & Back
    >>High Credit Score fullz (700+ Scores)
    >>DL number, Employee Details, Bank Details Included
    >>Complete Premium Info with Relative Info

    ***************************************
    COMPLETE GUIDE FOR TUTORIALS & TOOLS

    "SPAMMING" "HACKING" "CARDING" "CASH OUT"
    "KALI LINUX" "BLOCKCHAIN BLUE PRINTS" "SCRIPTING"
    "FRAUD BIBLE"

    "TOOLS & TUTORIALS LIST"
    =>Ethical Hacking Ebooks, Tools & Tutorials
    =>Bitcoin Hacking
    =>Kali Linux
    =>Fraud Bible
    =>RAT
    =>Keylogger & Keystroke Logger
    =>WhatsApp Hacking & Hacked Version of WhatsApp
    =>Facebook & Google Hacking
    =>Bitcoin Flasher
    =>SQL Injector
    =>Premium Logs (PayPal/Amazon/Coinbase/Netflix/FedEx/Banks)
    =>Bitcoin Cracker
    =>SMTP Linux Root
    =>Shell Scripting
    =>DUMPS with pins track 1 and 2 with & without pin
    =>SMTP's, Safe Socks, Rdp's brute
    =>PHP mailer
    =>SMS Sender & Email Blaster
    =>Cpanel
    =>Server I.P's & Proxies
    =>Viruses & VPN's
    =>HQ Email Combo (Gmail, Yahoo, Hotmail, MSN, AOL, etc.)

    *Serious buyers will always welcome
    *Price will be reduce in bulk order
    *Discount offers will give to serious buyers
    *Hope we do a great business together

    ===>Contact 24/7<===
    ==>Telegram > @leadsupplier
    ==>ICQ > 752822040
    ==>Skype > Peeterhacks
    ==>Wicker me > peeterhacks

    ReplyDelete
  17. What's Up Everyone

    Fresh Databases available

    CC's CVV's SSN
    Pros High Credit Scores 700+
    Fullz/Leads with SSN+DOB+DL
    Dumps
    EIN Leads
    Bulk HQ Emails
    Office365 Emails & Logs

    >>>WA/Telegram +92 317 272 1122
    >>>ICQ 752822040
    >>>Skype/Wickr @peeterhacks
    >>>Email exploit dot tools4u at gmail dot com

    Quality Tools & Tutorials available for
    HACKING|SPAMMING|CARDING|SPYING|CLONING|CASH-OUTS|TRANSFERS

    Legit Fullz/Pros/Leads will be provided
    Bulk quantity also
    Invalid stuff will be replaced/No refund
    BTC & USDT payments mode
    Available 24/7

    Feel Free to contact Guy's

    ReplyDelete
  18. We're providing fresh & valid info
    USA UK CANADA AUS RU FR CHINA

    FULLZ
    LOAN METHODS
    CARDING METHODS
    TAX RETURN FILLING

    ===================================
    Fresh spammed info available
    ===================================
    *SSN DOB DL
    *CC WITH CVV
    *HIGH CS PROS
    *DUMPS WITH PIN 101 & 202
    *DL SCAN FRONT & BACK WITH SELFIE
    *BUSINESS EIN FULLZ
    *SPECIFIC STATE|ZIP|CITIES|GENDER FULLZ
    *FULLZ FOR KYC/TAX RETURN/UI/PUA
    *OFFICE365 LEADS & LOGINS
    *PASSPORTS

    FOR QUERY CONTACT
    ->Telegram @killhacks/@leadsupplier
    ->ICQ 752822040 / @killhacks
    ->Email hacksp007 @ DNMX.org
    ->WhatsApp (will be given on demand)

    SSN DOB DL INFO
    firstname+lastname+ssn+dob+dlnumber+dlstate+address+city+state+zip+phonehome+phonecell+email+netincome+employmentstatus+employername+phonework+bankname+routingno+accountno
    Dora|Yotter Zayas|874646790|10/19/1955|Y362176558790|FL|4736 Grapevine Way|Davie|FL|33331|5052363136|8008526829|dzayas@legalclub.com|3250|benefits|n/a|n/a|8008526829|BANK OF AMERICA|5054473196|63100277

    CC WITH CVV INFO
    CCnumber+expmm+expyyyy+cvv+Fullname+Address+City+State+Zip+ssn+dob+phonenmuber
    4266902012413017|12|23|223|Spencer D Olmstead|4394 Westminster pl|Columbus|Indiana|47201|315-02-6111|18/09/1981|8123432114

    __________________________________________________________________________
    TOOLS & TUTORIALS FOR HACKING|SPAMMING|CARDING|SCRIPTING|CLONING|CRACKING
    __________________________________________________________________________

    SMTP's|RDP's|SHELLS|BRUTES
    C-PANELS|WEB-MAILERS|MAILERS|SENDERS
    KEYLOGGERS|VIRUSES|RATS
    KALI LINUX MASTER CLASS
    SMTP LINUX ROOT
    EMAIL's|I.P's|COMBOS|PROXIES
    SPAMMING COMPLETE PACKAGE
    SCAM PAGES|SCAM PAGE SCRIPTING
    HACKING TOOLS & TUTORIALS
    CC TOP UP METHODS
    CC CHECKERS

    Many other Tools & Tutorials we can provide on demand
    Easy to learn & easy to earn
    Guidance will be provided if needed
    Tutorials & Methods will be up to date

    *HIT ME UP FOR ORDER*
    ->Telegram @killhacks/@leadsupplier
    ->ICQ 752822040 / @killhacks
    ->Email hacksp007 @ DNMX.org
    ->WhatsApp (will be given on demand)

    ReplyDelete
  19. -----------------------------
    @cpanelmaster - Tele Gram.
    @cpanelmaster - icq.
    https://toolz.store - Visit My Web Site
    ------------------------------

    ***Best Spamming Tools And Scam Page Service are available.***

    Tools we are offeing like;

    *Windows RDP
    *inbox SMTP
    *SMS Leads-Phone Number
    *Email Leads
    *Office 365 Email Leads
    *Bulk Phone Number
    *Residential Proxy
    *Email Extractor
    *Bank logs from ALL countries
    *Fullz Debit/Credit Card
    *cPanel hosting
    *WHM
    *SSN DOB DL data With Id pictures and Selfie

    -Guaranteed Tools.
    -Demo Will be shown after making deal done.

    ReplyDelete